opentrade-portfolio

Warn

Audited by Socket on Mar 19, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS. The skill's portfolio-checking behavior and token requirement fit its stated purpose, but its execution model relies on repeated raw GitHub pipe-to-shell installation of an external CLI and then passes API credentials to that CLI. The main concern is supply-chain and credential-forwarding trust, not clear evidence of malicious intent.

Confidence: 81%Severity: 74%
Audit Metadata
Analyzed At
Mar 19, 2026, 04:09 AM
Package URL
pkg:socket/skills-sh/6551team%2Fopenskills%2Fopentrade-portfolio%2F@1e7543555507e1fa766ccc64a7adaab9295614db